QuestionQ28

Security and Compliance

A company has a VPC that includes a public subnet and a private subnet. The company deploys an Amazon EC2 instance in the private subnet using an Amazon Linux Amazon Machine Image (AMI), with the AWS Systems Manager Agent (SSM Agent) installed. The EC2 instance belongs to a security group that permits outbound traffic only.

A CloudOps engineer must enable a group of privileged administrators to connect to the instance through SSH without exposing the instance to the internet.

Which solution meets this requirement?

Explanation

An EC2 Instance Connect Endpoint provides an identity-aware private TCP proxy for connecting to instances that do not have public IP addresses. The endpoint’s security group must be allowed to reach the destination instance, so permitting inbound SSH to the instance from the endpoint enables SSH without internet exposure. EC2 Instance Connect Endpoint access is governed through IAM permissions, and PowerUserAccess grants broad access to EC2 capabilities. Connect to your instances using a private IP address and EC2 Instance Connect Endpoint

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!